Configuring VPN Settings
To configure the required Remote Access VPN settings:
-
In SmartConsole > Security Policies tab, right click the Security Gateway and select Edit.
The Check Point Gateway window opens.
-
Enable VPN functionality: In the General Properties page, in the Network Security tab, select the IPSec VPN blade.
Note - This enables all IPsec VPN functionality.
-
Add the Security Gateway to the Remote Access VPN community:
-
From the Security Gateway Properties tree, click IPsec VPN.
-
Under This Security Gateway Participates in the following VPN Communities, click Add.
-
In the window that opens, select Remote Access.
-
Click OK.
-
-
Set the VPN domain for the Remote Access community:
-
From the Security Gateway Properties tree, select Network Management > VPN Domain.
-
Click Set domain for Remote Access Community.
-
In the window that opens, select the Remote Access VPN Community and click Set.
-
In the window that opens, select a VPN Domain and click OK, or click New and define a VPN domain.
-
Click OK.
-
-
Configure Visitor Mode:
-
From the Security Gateway Properties tree, select VPN Clients > Remote Access.
-
Select Support Visitor Mode and leave All Interfaces selected.
-
Optional: Choose the Visitor Mode Service, which defines the protocol and port of Endpoint Security VPN connections to the Security Gateway.
-
-
Configure Office Mode:
-
From the Security Gateway Properties tree, select Office Mode.
-
Select an option: Offer Office Mode to group or Allow Office Mode to all users.
-
Select an Office Mode Method.
-
Click OK.
Note - Office mode is not supported in SecuRemote. If you use SecuRemote, you can select Do not offer Office Mode. If another option is selected, it is ignored.
-
To add Remote Access Clients users to the VPN Community:
-
In SmartConsole, Security Policies tab, under Access Tools, click VPN Communities.
-
In the list of VPN Communities, double click the RemoteAccess community.
-
From the tree, select Participant User Groups.
-
Make sure all Remote Access clients users are included.
-
You can leave All Users.
-
You can click the plus sign to add existing user groups to the community.
-
-
Select Participating Gateways.
-
Make sure that the Security Gateway you configured for remote access is listed.
-
Click OK.
To configure encryption for the VPN:
-
From the SmartConsole menu, select Global Properties.
-
Select Remote Access > VPN - Authentication and Encryption.
-
In Encryption Algorithms, click Edit.
-
In Support encryption algorithms - Make sure that at least one AES encryption algorithm is selected.
-
In Use encryption algorithm - Make sure that at least one AES encryption algorithm is selected.
-
-
Click OK.
-
Click OK.
Important - The client does not support DES algorithms. An AES algorithm must be selected.
You can enable support for DES algorithms, if you also enable support for at least one AES algorithm.